# Checklist actions and task file

These routes wrap `tasks.task.checklist.*` and `tasks.task.files.attach`. This is a different Bitrix24 method family from the [older `task.checklistitem.*` routes](./checklist.md). Every call needs an API key with the `task` or `tasks` scope and write access. Each response is `{ "success": true, "data": <Bitrix24 result> }`: the `result` value is passed through. Bitrix24 errors use the standard `/v1` error handling.

| Method and path | Bitrix24 | JSON body |
| --- | --- | --- |
| `POST /v1/tasks/:taskId/checklist/tree` | `tasks.task.checklist.save` | `{ "items": [...], "parameters"?: { ... } }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/complete-all` | `tasks.task.checklist.completeAll` | not required |
| `POST /v1/tasks/:taskId/checklist/:itemId/move-before` | `tasks.task.checklist.moveBefore` | `{ "beforeItemId": 123 }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/move-after` | `tasks.task.checklist.moveAfter` | `{ "afterItemId": 123 }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/members` | `tasks.task.checklist.addMembers` | `{ "members": { "42": "A" } }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/members/remove` | `tasks.task.checklist.removeMembers` | `{ "membersIds": [42] }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/attachments/content` | `tasks.task.checklist.addAttachmentByContent` | `{ "attachmentParameters": { "NAME": "file.txt", "CONTENT": "<base64>" } }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/attachments/disk` | `tasks.task.checklist.addAttachmentsFromDisk` | `{ "filesIds": [123] }` |
| `POST /v1/tasks/:taskId/checklist/:itemId/attachments/remove` | `tasks.task.checklist.removeAttachments` | `{ "attachmentsIds": [456] }` |
| `POST /v1/tasks/:taskId/files/attach` | `tasks.task.files.attach` | `{ "fileId": 123 }` |

`taskId` and `itemId` are positive integers. `save` forwards the `items` array unchanged: Bitrix24 builds the tree and checks permissions. The array is flat: each item has a unique `NODE_ID`, a root sets `PARENT_NODE_ID: 0`, and a child references its parent's `NODE_ID` through `PARENT_NODE_ID`. A new item needs `TITLE`; the controller does not save a nested `CHILDREN` field.

`save` **replaces the entire task checklist**: existing items omitted from `items` are deleted. `"items": []` deletes every item. To preserve an existing row, include its uppercase `ID` with the complete current set; without `ID`, Bitrix24 creates a new row and deletes the old one. A successful call with a non-empty array returns `data.checkListItem.traversedItems` as an object keyed by `NODE_ID`, with `data.checkListItem.taskId: null`. With an empty array, `data.checkListItem` is `[]`.

```json
{"items":[{"ID":9,"NODE_ID":"root-1","PARENT_NODE_ID":0,"TITLE":"Prepare release","IS_COMPLETE":false,"IS_IMPORTANT":false},{"NODE_ID":"child-1","PARENT_NODE_ID":"root-1","TITLE":"Review checklist","IS_COMPLETE":false,"IS_IMPORTANT":false}]}
```

`completeAll` returns an array of items, item actions return a `checkListItem` object, and `files.attach` returns an `attachmentId` object whose ID identifies the **link** between the file and task. `fileId` identifies an existing Drive file. This route does not upload a file.

Content for `addAttachmentByContent` is base64 inside JSON; the normal `/v1` request body limit applies (1 MiB). This route does not add multipart or URL transport.
